Vulnerability in roundcube allows information disclosure
From RC ML:
After getting reports about a possible vulnerability of Roundcube
which allows an attacker to modify its users preferences in a way that
he/she can then read files from the server, we now published updated
packages as well as patches that fix this security issue.
Please update all your Roundcube installations with the new versions
(0.9-rc2, 0.8.6, 0.7.4) or patch them with the published patches.
Download the latest version from http://roundcube.net/download
In order to find out whether one of your users has vulnerable
preferences, you can run the following query on the Roundcube user
SELECT * FROM users WHERE preferences LIKE ‘generic_message_footer’
If this returns any results, you should at least clear the
‘preferences’ field of that user entry. Or better: entirely block the
user because he or she most likely tried to exploit your system.
And here’s some background about the vulnerability:
(from redmine: issue id 1738, created on 2013-03-28, closed on 2013-04-12)
- child #1739
- child #1740
- child #1741
- child #1742
- Revision edb0fdb8 on 2013-03-28T09:55:49Z:
main/roundcubemail: security upgrade to 0.8.6. Fixes #1738